First published: Tue Dec 12 2017(Updated: )
SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Internet Transaction Server | ||
Sap Business Application Software Integrated Solution | >=7.00<=7.02 | |
Sap Business Application Software Integrated Solution | >=7.50<=7.52 | |
Sap Business Application Software Integrated Solution | =7.30 | |
Sap Business Application Software Integrated Solution | =7.31 | |
Sap Business Application Software Integrated Solution | =7.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-16682.
The severity of CVE-2017-16682 is high (7.2).
SAP Basis versions 7.00 to 7.02, 7.30, 7.31, 7.40, and 7.50 to 7.52 are affected.
An attacker with administrator credentials can inject code that can be executed by the application.
You can find more information about CVE-2017-16682 at the following references: SecurityFocus, SAP Blogs, and SAP Support Notes.